GPU VulnDB

Database/NVIDIA / GPU stack

Linux kernel drm/amdgpu: unbounded VBIOS GPIO I2C entry count overruns adev->i2c_bus[]

UnscoredCVE-2026-97493NVIDIA / GPU stackcurated

Impact

amdgpu derived the number of GPIO I2C bus entries from a size field in the VBIOS image without rejecting undersized tables or capping the count at AMDGPU_MAX_I2C_BUS, so a corrupt or tampered VBIOS makes the driver write past adev->i2c_bus[] or iterate an absurd number of entries. This runs during driver probe on the host, so the failure mode on an Instinct node is a kernel memory overrun at boot or module load rather than something a tenant workload triggers. The input is the card's own VBIOS, which means reaching it requires either physical or already-privileged access to reflash the GPU, or a genuinely corrupted board - so this is a robustness fix for a hostile or damaged firmware image, not a tenant-reachable escalation path.

Who can reach it

Not reachable from a tenant GPU pod. The attacker must control the VBIOS content the driver reads - physical access to the card, or root on the host with the ability to flash GPU firmware. Also fires on genuinely corrupt VBIOS size fields with no attacker at all.

What to do

Take the stable kernel fix in drm/amdgpu and reboot the node to load the patched driver - drain and reboot on the normal kernel-update cadence, no GPU firmware flash required for the fix itself. If a node is faulting here already, treat the card's VBIOS as suspect and verify or reflash it with the node out of service.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.